ReferenceCloud

Cloud

bro command reference for cloud.

16 min readEdit this page

See Init and config for shared conventions and environment variables.

bro cloud login either runs the RFC 8628 Device Authorization Grant or stores an existing BitRouter API key. Both credential types live under $XDG_DATA_HOME/bitrouter/account-credentials.json (mode 0600 on Unix). The API-key form performs no network request, which makes it suitable for CI. Interactive OAuth lets you pick the workspace this session is bound to; tokens refresh automatically within 60 s of expiry.

The default scope set covers inference:invoke, usage:read, keys:read/keys:write, billing:read, policy:read/policy:write, byok:read/byok:write, and namespace:read. Sensitive scopes such as billing:write are opt-in via --scope. After either login form, the bitrouter provider auto-enables in zero-config mode — every model your account is entitled to is routable as bitrouter:<model-id>.

Every leaf accepts --json for raw output; the default is a systemctl-style key:value block for single resources and a small table for lists. When the server returns 403 missing required scope: <s>, OAuth users get a copy-pasteable re-login hint; API-key users are told to mint a key with that scope.

bro cloud

Manage your BitRouter Cloud account — sign in/out, namespaces, keys, usage, requests, billing, policies, budgets, presets, and BYOK. Start with cloud login

Usage: bro cloud <COMMAND>

bro cloud whoami

Print the cloud identity stored on this machine alongside the /v1/* base URL the CLI will target

Usage: bro cloud whoami

bro cloud api

Make an authenticated request to a relative BitRouter Cloud API endpoint

Usage: bro cloud api [OPTIONS] <ENDPOINT>

ArgumentDescription
<ENDPOINT>Relative API endpoint, for example /v1/models
FlagDescription
-X, --method <METHOD>HTTP method. Defaults to GET, or POST when fields/input are present
-H, --header <KEY:VALUE>Add an HTTP request header. May be repeated
-f, --raw-field <KEY=VALUE>Add a string field to the JSON body or query string. May be repeated
-F, --field <KEY=VALUE>Add a typed field to the JSON body or query string. May be repeated
--input <FILE>Read the exact request body from a file, or - for stdin
-i, --includeInclude the response status line and headers in stdout
--silentSuppress the response body
--verbosePrint redacted request and response details to stderr

Modeled after gh api: injects the stored bearer against the logged-in origin and streams the response. Absolute URLs and redirect following are rejected, so the credential never leaves its login origin.

bro cloud api /v1/models
bro cloud api /v1/chat/completions --input request.json
bro cloud api /v1/responses -f model=openai/gpt-5 -F stream=true

bro cloud login

Sign in to BitRouter Cloud from this terminal. Prints a verification URL — open it, approve, and this CLI stores an access token it refreshes automatically. This is the same credential the built-in bitrouter provider uses for inference, so providers login bitrouter is an alias for this command.

Usage: bro cloud login [OPTIONS]

FlagDescription
--oauth-as <URL>Authorization server URL. Defaults to <https://api.bitrouter.ai>; override only for a self-hosted deployment (env: BITROUTER_OAUTH_AS)
--client-id <ID>OAuth client id. Defaults to bitrouter-cli; override only for a self-hosted deployment (env: BITROUTER_OAUTH_CLIENT_ID)
--scope <SCOPE>Permissions to request, as a space-delimited list. Defaults to a broad "developer" set; pass a narrower or wider list to override (env: BITROUTER_OAUTH_SCOPE)
--api-key <BRK_API_KEY>Authenticate with a BitRouter API key instead of OAuth. Intended for CI and other non-interactive environments
bro cloud login                              # device flow, pick a workspace
bro cloud login --api-key "$BITROUTER_API_KEY"   # CI: no network, no browser

bro cloud logout

Sign out: revoke the stored token at the server (best-effort) and delete the local credentials file

Usage: bro cloud logout [OPTIONS]

FlagDescription
--oauth-as <URL>Override the authorization server URL recorded in the credentials file for the revocation call
--client-id <ID>Override the recorded OAuth client id for the revocation call

bro cloud namespace

Inspect the namespaces you own and the one this CLI is bound to

Usage: bro cloud namespace <COMMAND>

bro cloud namespace list

List the namespaces you own. The one this CLI is signed in to is marked (active). Switching namespaces is a re-login: bro cloud login and pick a different namespace in the browser

Usage: bro cloud namespace list [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud namespace current

Print the namespace this CLI's credential is bound to. Offline — reads the local credential, no network call

Usage: bro cloud namespace current [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud keys

Manage brk_ API keys in your namespace

Usage: bro cloud keys <COMMAND>

bro cloud keys list

List API keys on your account

Usage: bro cloud keys list [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud keys mint

Mint a new API key. The plaintext is printed once

Usage: bro cloud keys mint [OPTIONS] --name <NAME>

FlagDescription
--name <NAME>Operator-supplied display name
--scope <SCOPE>Wire-format scope tokens (repeat the flag, or pass a single space-delimited list). Must be a subset of your effective scopes
--expires-at <EXPIRES_AT>Optional expiry (RFC 3339, e.g. 2026-12-31T00:00:00Z)
--jsonPrint the response as raw JSON instead of the human-readable summary

Returns the plaintext brk_… token exactly once — the server keeps only the SHA-256 hash. Requested scopes must be a subset of your effective scopes.

bro cloud keys mint --name ci --scope "policy:read usage:read"

bro cloud keys revoke

Revoke a key by id

Usage: bro cloud keys revoke [OPTIONS] <ID>

ArgumentDescription
<ID>The key id (e.g. k_…)
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud usage

Read aggregate spend / token counts for your account

Usage: bro cloud usage [OPTIONS]

FlagDescription
--from <FROM>Lower bound (RFC 3339). Defaults to to - 30 days
--to <TO>Upper bound (RFC 3339). Defaults to now
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud requests

Page through recent inference requests

Usage: bro cloud requests [OPTIONS]

FlagDescription
--limit <LIMIT>Page size (server clamps to [1, 100])
--offset <OFFSET>Offset into the result set
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud billing

Credit balance and Stripe checkout

Usage: bro cloud billing <COMMAND>

bro cloud billing balance

Show the account's credit balance

Usage: bro cloud billing balance [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud billing checkout

Start a Stripe checkout session for a credit top-up. Requires the billing:write scope

Usage: bro cloud billing checkout [OPTIONS] --amount-cents <AMOUNT_CENTS>

FlagDescription
--amount-cents <AMOUNT_CENTS>Amount in USD cents
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy

Generic CRUD over the typed policy registry

Usage: bro cloud policy <COMMAND>

--spec reads a JSON file (or - for stdin) holding the flat inner spec body — e.g. {"window": "day", "limit_micro_usd": 5000000} for a budget. effective and for-principal answer "what would happen to a request from this principal" without making an inference call. budget and preset are typed sugar over the same rows.

bro cloud policy list

List policies on your account

Usage: bro cloud policy list [OPTIONS]

FlagDescription
--kind <KIND>Narrow the list to one kind [possible values: budget, rate-limit, guardrail, preset]
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy get

Fetch one policy

Usage: bro cloud policy get [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy create

Create a policy. Spec body is read from --spec <file\|->

Usage: bro cloud policy create [OPTIONS] --name <NAME> --kind <KIND> --spec <SPEC>

FlagDescription
--name <NAME>Operator-supplied display name
--kind <KIND>Kind discriminator — selects which shape --spec must take [possible values: budget, rate-limit, guardrail, preset]
--spec <SPEC>Path to a JSON file containing the flat inner spec body, or - to read from stdin
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy update

Update a policy's name and / or spec

Usage: bro cloud policy update [OPTIONS] <ID>

ArgumentDescription
<ID>The policy id
FlagDescription
--name <NAME>New name. Omit to leave unchanged
--spec <SPEC>New spec. Path to a JSON file or - for stdin. Omit to leave unchanged
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy delete

Delete a policy

Usage: bro cloud policy delete [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy bind

Attach a policy to a principal

Usage: bro cloud policy bind [OPTIONS] --principal-type <PRINCIPAL_TYPE> --principal-id <PRINCIPAL_ID> <ID>

ArgumentDescription
<ID>The policy id
FlagDescription
--principal-type <PRINCIPAL_TYPE>Principal kind (namespace, api_key, oauth_token, oauth_client)
--principal-id <PRINCIPAL_ID>Principal id — interpretation depends on --principal-type
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy unbind

Detach one binding from a policy

Usage: bro cloud policy unbind [OPTIONS] <ID> <BINDING_ID>

ArgumentDescription
<ID>The policy id
<BINDING_ID>The binding id (from cloud policy bindings <id>)
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy disable

Park a policy — the engine skips it at request time

Usage: bro cloud policy disable [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy enable

Re-enable a previously disabled policy

Usage: bro cloud policy enable [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy bindings

List the bindings of one policy

Usage: bro cloud policy bindings [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy effective

Preview the effective policy for a principal

Usage: bro cloud policy effective [OPTIONS] --principal-type <PRINCIPAL_TYPE> --principal-id <PRINCIPAL_ID>

FlagDescription
--principal-type <PRINCIPAL_TYPE>Principal kind (namespace, api_key, oauth_token, oauth_client)
--principal-id <PRINCIPAL_ID>Principal id
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud policy for-principal

List every policy bound to a principal

Usage: bro cloud policy for-principal [OPTIONS] <PRINCIPAL_TYPE> <PRINCIPAL_ID>

ArgumentDescription
<PRINCIPAL_TYPE>Principal kind
<PRINCIPAL_ID>Principal id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud budget

Typed wrapper over budget-kind policies

Usage: bro cloud budget <COMMAND>

bro cloud budget list

List every budget on the account

Usage: bro cloud budget list [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud budget get

Fetch one budget

Usage: bro cloud budget get [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud budget create

Create a budget

Usage: bro cloud budget create [OPTIONS] --name <NAME> --window <WINDOW> --limit-micro-usd <LIMIT_MICRO_USD>

FlagDescription
--name <NAME>Display name
--window <WINDOW>Rolling-spend window [possible values: day, month, total]
--limit-micro-usd <LIMIT_MICRO_USD>Spend cap in micro-USD (must be strictly positive)
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud budget update

Patch a budget's fields

Usage: bro cloud budget update [OPTIONS] <ID>

ArgumentDescription
<ID>The budget id
FlagDescription
--name <NAME>New name
--window <WINDOW>New window [possible values: day, month, total]
--limit-micro-usd <LIMIT_MICRO_USD>New cap (must be strictly positive when supplied)
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud budget delete

Remove a budget

Usage: bro cloud budget delete [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud preset

Typed wrapper over preset-kind policies

Usage: bro cloud preset <COMMAND>

bro cloud preset list

List every preset on the account

Usage: bro cloud preset list [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud preset get

Fetch one preset

Usage: bro cloud preset get [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud preset create

Create a preset. Each clause is supplied as a JSON file (or - for stdin)

Usage: bro cloud preset create [OPTIONS] --name <NAME>

FlagDescription
--name <NAME>Display name
--guardrail <GUARDRAIL>Optional guardrail clause (JSON file or -)
--budget <BUDGET>Optional budget clause
--rate-limit <RATE_LIMIT>Optional rate-limit clause
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud preset update

Patch a preset's clauses. Use --clear-* to drop a clause

Usage: bro cloud preset update [OPTIONS] <ID>

ArgumentDescription
<ID>The preset id
FlagDescription
--name <NAME>New name
--guardrail <GUARDRAIL>Replace the guardrail clause (JSON file or -)
--budget <BUDGET>Replace the budget clause
--rate-limit <RATE_LIMIT>Replace the rate-limit clause
--clear-guardrailDrop the guardrail clause
--clear-budgetDrop the budget clause
--clear-rate-limitDrop the rate-limit clause
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud preset delete

Remove a preset

Usage: bro cloud preset delete [OPTIONS] <ID>

ArgumentDescription
<ID>The resource id
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud byok

Bring-your-own-key provider keys

Usage: bro cloud byok <COMMAND>

bro cloud byok list

List every BYOK row on the account

Usage: bro cloud byok list [OPTIONS]

FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

bro cloud byok set

Upsert a BYOK row. Ciphertext must be sealed by the caller against the cloud's current X25519 public key

Usage: bro cloud byok set [OPTIONS] --provider <PROVIDER> --ciphertext-b64 <CIPHERTEXT_B64> --kek-id <KEK_ID> --key-prefix <KEY_PREFIX>

FlagDescription
--provider <PROVIDER>Upstream provider id (e.g. anthropic)
--ciphertext-b64 <CIPHERTEXT_B64>Base64-encoded sealed-box ciphertext
--kek-id <KEK_ID>KEK id used to seal --ciphertext-b64. Must match the cloud's current primary_kek_id
--key-prefix <KEY_PREFIX>Operator-visible prefix of the underlying plaintext
--api-base <API_BASE>Override API base for the provider
--jsonPrint the response as raw JSON instead of the human-readable summary

Ciphertext must be sealed against the cloud's current X25519 public key before submission — the server only stores already-encrypted bytes. Fetch the current key from GET /v1/byok/encryption-pubkey first.

bro cloud byok delete

Remove a BYOK row by provider id

Usage: bro cloud byok delete [OPTIONS] <PROVIDER>

ArgumentDescription
<PROVIDER>Provider id (the row's provider_name)
FlagDescription
--jsonPrint the response as raw JSON instead of the human-readable summary

How is this guide?

On this page